Defending APIs with Jim Manico

November 10, 2022 | 9am PST | 5pm BST

Webinar Series - Defending APIs with Jim Manico

Watch the Webinar

Join Jim Manico, CEO of Manicode and Colin Domoney from 42Crunch, as they deliver a 2-part webinar series to help developers better defend APIs.

Episode 1: Request Forgery on the Web - CSRF & SSRF

In this first episode Jim and Colin will discuss request forgery and how to prevent it. This technical talk is intended for the software developer who needs to build secure web applications and APIs. it will cover the two variants of request forgery —  client-side (CSRF) and server-side (SSRF).

  • CSRF is most widely associated with vulnerable web applications that trick a user in a client browser into submitting transactions they never intended to use in their current authenticated session. We will discuss historical CSRF attacks and investigate various well-proven defense strategies. For API developers we will investigate whether APIs are vulnerable to CSRF, and how to prevent it.
  • SSRF attacks allow a malicious client to trick a vulnerable server into submitting requests to an unintended location, typically by submitting malformed URLs in payloads and relying on vulnerabilities in the URL parsing code. We will discuss prevention strategies and examine some well-known examples. For API developers, we will investigate ways in which SSRF can be directed at vulnerable APIs and examine a few recent API breaches and the latest research.


Colin Domoney 2

Colin Domoney

Developer Advocate & API Security Researcher




jimmanico BW

Jim Manico


Manicode Security



Webinar Partner

At Manicode Security 100% of their focus is teaching developers to write secure code. They bring a combination of passion, style and decades of research into all of their education offerings.

Partnered with: Manicode Security

Manicode Logo

Latest Resources


Addressing API Security Regulations in Financial Services

By Colin Domoney | April 10, 2024

Introduction APIs are disrupting almost every industry vertical, and nowhere is their impact more profound than in the financial services industry. Whether helping modernize legacy systems or creating entirely new business opportunities through innovations such as OpenBanking, APIs are the lifeblood of the financial services industry. At the […]


42Crunch And Microsoft’s Defender for Cloud Partner to Deliver End-to-End API Security

By Newsdesk | November 15, 2023

San Francisco, CA, November 15, 2023 10AM PST
42Crunch and Microsoft integrate services to help enterprises adopt a full-lifecycle approach to API security
Today 42Crunch, the API DevSecOps platform, announced the integration of 42Crunch’s API security audit and vulnerability testing solution with Microsoft Defender for Cloud to provide Microsoft customers continuous API protection from design to runtime.


APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Ready to Learn More?

Developer-first solution for delivering API security as code.